Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39001
HistoryJan 25, 2023 - 3:22 a.m.

Regular Expression Denial Of Service (ReDoS)

2023-01-2503:22:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
vulnerability
rack
parser
rfc2183-multipart-boundary
redos

0.001 Low

EPSS

Percentile

39.8%

rack is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability exists in get_filename function of parser.rb due to inefficient regular expression complexity which allows an attacker to crash the application by submitting a malicious input with a RFC2183-multipart-boundary string.